Project

General

Profile

Actions

Bug #10700

closed

not all VPN IPs added with vpnaddresses option

Added by Viktor Gurov almost 4 years ago. Updated over 3 years ago.

Status:
Resolved
Priority:
Normal
Category:
Suricata
Target version:
-
Start date:
06/25/2020
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:

Description

Suricata uses filter_get_vpns_list() to get vpnaddresses list

filter_get_vpns_list() returns only:
IPsec Mobile IPv4 subnet
IPsec site-to-site networks
OpenVPN client/server Tunnel Network / Remote Network IPv4
PPPoE server networks

but not:
IPsec Mobile IPv6 subnet
IPsec Mobile warriors IPs (VPN / IPsec / Pre-Shared Keys / Edit)
OpenVPN client/server Tunnel Network / Remote Network IPv6
L2TP VPN network

See also #8688 and #10493

Actions #2

Updated by Jim Pingle almost 4 years ago

  • Status changed from New to Pull Request Review
Actions #3

Updated by Renato Botelho almost 4 years ago

  • Status changed from Pull Request Review to Feedback
  • Assignee set to Renato Botelho
  • % Done changed from 0 to 100

PR has been merged. Thanks!

Actions #4

Updated by Viktor Gurov almost 4 years ago

Actions #5

Updated by Max Leighton over 3 years ago

Tested in Suricata 5.0.4_1 and 6.0.0_4. I'm seeing all of the relevant VPN IPs added to the list.

Actions #6

Updated by Renato Botelho over 3 years ago

  • Status changed from Feedback to Resolved
Actions

Also available in: Atom PDF